Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 197574 (CVE-2007-5731) - dev-java/jakarta-slide-webdavclient Remote File Disclosure (CVE-2007-5731)
Summary: dev-java/jakarta-slide-webdavclient Remote File Disclosure (CVE-2007-5731)
Status: RESOLVED INVALID
Alias: CVE-2007-5731
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/27467/
Whiteboard: ~3? [ebuild?]
Keywords:
Depends on:
Blocks:
 
Reported: 2007-10-31 00:20 UTC by Robert Buchholz (RETIRED)
Modified: 2007-11-12 22:03 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2007-10-31 00:20:27 UTC
CVE-2007-5731 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5731):
  Absolute path traversal vulnerability in Apache Jakarta Slide 2.1 and earlier
  allows remote authenticated users to read arbitrary files via a WebDAV write
  request that specifies an entity with a SYSTEM tag, a related issue to
  CVE-2007-5461.
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2007-10-31 00:23:45 UTC
This bug is related to bug #196066.

Java, please advise.
Comment 2 Petteri Räty (RETIRED) gentoo-dev 2007-11-01 00:29:00 UTC
(In reply to comment #1)
> This bug is related to bug #196066.
> 
> Java, please advise.
> 

Well it's not stable so at least we don't have those machines affected. There is no new upstream release available or patches in the security reports so don't really know if we can do much.
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2007-11-04 08:38:49 UTC
The error is fixed in the SVN. I don't know their release cycle, is there a new RC close?

$ svn log  -r 590978 http://svn.apache.org/repos/asf/jakarta/slide
------------------------------------------------------------------------
r590978 | ozeigermann | 2007-11-01 13:27:06 +0100 (Thu, 01 Nov 2007) | 3 lines

Quick-fix for security issue raised here

www.milw0rm.com/exploits/4567
------------------------------------------------------------------------
Comment 4 Robert Buchholz (RETIRED) gentoo-dev 2007-11-12 02:40:45 UTC
Petteri, can you include the patch in case they do not release?
Comment 5 Petteri Räty (RETIRED) gentoo-dev 2007-11-12 21:26:12 UTC
(In reply to comment #4)
> Petteri, can you include the patch in case they do not release?
> 

That patch is for some server code. jakarta-slide-webdavclient is client side code  so the patch doesn't have much to do with this package. As this seems to be a server issue I think this bug is INVALID for jakarta-slide-webdavclient. Please reopen if you don't agree.
Comment 6 Robert Buchholz (RETIRED) gentoo-dev 2007-11-12 22:03:06 UTC
ACK, you're right.